Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-11373

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections.<br /> <br /> Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd.<br /> <br /> Newlines are not removed from metric names, allowing metric injections.<br /> <br /> Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
22/06/2026

CVE-2026-12580

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users&amp;#39; browsers upon page load.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/06/2026

CVE-2026-12581

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user&amp;#39;s privilege once the user logs in.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/06/2026

CVE-2026-12862

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/06/2026

CVE-2026-12863

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** An unvalidated redirect was contained in Venueless&amp;#39; social login functionality and could be exploited for phishing using trusted domains.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/06/2026

CVE-2023-45796

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/06/2026

CVE-2025-4994

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device&amp;#39;s configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an attacker within wireless range can gain unauthorized administrative access to the device configuration.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/07/2026

CVE-2023-45795

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/06/2026

CVE-2026-54665

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict values provided in the HTTP Host header, but did not apply the validation to alternative Proxy and Forwarded headers. The absence of proxy host header validation allowed a client to instruct Apache NiFi web services to construct invalid qualified URLs for redirection or data references. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which implements validation for the X-ProxyHost and X-Forwarded-Host HTTP request headers based on the nifi.web.proxy.host property. Enabling header validation requires configuring the application with HTTPS. Reverse proxy servers in front of Apache NiFi are responsible for filtering input request headers and providing allowed values to the application.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/06/2026

CVE-2026-44914

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization permits a user with general write access to add components with Restricted status. Apache NiFi installations that do not implement specific authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, which removes the implementation of Restricted status authorization from the framework.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/06/2026

CVE-2026-44913

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover additional strategies. Apache NiFi installations that do not use the CaptureChangeMySQL Processor are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which incorporates more robust identifier escaping.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/06/2026

CVE-2026-44911

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying component configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, requiring write access to submit configuration verification requests.
Gravedad CVSS v4.0: BAJA
Última modificación:
23/06/2026